Cyber Incident Victim: Mindray
Timeline
Summary
The Cl0p ransomware group exploited a vulnerability in PTC’s Windchill product lifecycle management platform to gain unauthorized access and exfiltrate data from multiple organizations, including the global medical technology leader Mindray. According to the group’s disclosures, the stolen information for each victim spans databases, project files, backups, images, engineering documents, blueprints, diagrams, logs and other corporate files, with volumes ranging from one gigabyte to several terabytes. The article notes that much of the stolen data may be of little value or already public, and many of the named organizations have not confirmed paying a ransom despite being aware of the allegations.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
In June 2026, CISA added CVE-2026-12569, an improper input validation flaw in PTC’s Windchill PLM platform, to its KEV catalog and the vendor warned of attacks targeting it. Police in Germany reportedly alerted organizations about imminent exploitation of the vulnerability. By late July, cybersecurity observers noted that the Cl0p ransomware group was exploiting the flaw to deliver web shells inside Windchill environments. On August 12, 2026, Cl0p began publishing the full names of alleged victims on its leak site, having previously listed only partial names. Among the more than forty organizations named was the global medical technology leader Mindray.

The exploitation chain used a remote, unauthenticated attacker to achieve arbitrary code execution via specially crafted requests to the vulnerable Windchill service. Cl0p affiliates deployed a custom implant that provided full data theft capability without needing additional tools. This implant included a web shell that mapped sensitive vault data, decrypted every credential stored in the Windchill keystore, and incorporated a custom Java class loader allowing execution of any further code within the application process. The resulting backdoor enabled follow‑on activities such as lateral movement, ransomware deployment, or persistence. For each victim, including Mindray, the hackers listed the type and amount of information they claimed to have stolen, citing categories such as databases, project files, backups, photographs, image files, engineering documents, blueprints, diagrams, logs, and other corporate documents, with alleged exfiltration volumes ranging from one gigabyte to several terabytes per organization.
The article notes that the compromised files could contain sensitive personal information and valuable intellectual property, but that much of the data may be of little value and already public, which is why many of the targeted organizations have likely refused to pay a ransom. Companies such as Shell, Philips, Fiserv and GE stated they were aware of the claims and were investigating, though none had confirmed a significant data breach at the time of reporting. Mindray was included in the list of alleged victims, but no separate statement from the company is recorded in the source material.